Global Advice Network | Borgergade 111 | DK - 1300 Copenhagen K
E-Mail: info@business-anti-corruption.org | Phone: (+45) 60 88 10 44

Parent Company Duties for Subsidiary Corruption in China

A corruption incident involving a Chinese subsidiary can quickly become a group-wide compliance issue. The conduct may involve a local employee, sales intermediary, distributor, joint-venture partner, or senior manager, yet the consequences can reach the parent company through shared controls, financial benefits, management decisions, and reporting structures.

Chinese law does not automatically impose strict liability on a parent for every unlawful act committed by its subsidiary. The legal analysis depends on the parent’s role, the relationship between the entities, the nature of the payment, and the evidence showing what the parent knew or should have known. Separate exposure can also arise under the laws of the parent’s home country.

A responsible response therefore requires more than terminating the individual involved. The parent should preserve evidence, assess reporting duties, investigate independently, protect whistleblowers, and determine whether the subsidiary’s controls were adequate for the risks it faced in China.

How Chinese Law Connects Parent And Subsidiary Conduct

A subsidiary incorporated in China is generally a separate legal person. Its debts, contracts, employees, and regulatory obligations are ordinarily distinct from those of its parent. That separation is important, but it does not shield the parent from liability where the parent directly participated in the misconduct or created conditions that enabled it.

China’s Anti-Unfair Competition Law prohibits commercial bribery, including giving money or property to transaction counterparties or relevant personnel to obtain an improper business advantage. The law can apply to payments made through employees, agents, consultants, distributors, and other intermediaries. Administrative penalties may include fines, confiscation of unlawful gains, and reputational harm.

The Criminal Law may become relevant where conduct amounts to a serious bribery offense, such as bribery of public officials or commercial bribery involving significant amounts. Individual decision-makers are often the immediate targets of criminal enforcement, but a company can also face corporate criminal liability in circumstances defined by law. A parent that authorized, directed, funded, or knowingly assisted the conduct may face separate scrutiny.

The corporate veil is therefore not a complete compliance strategy. A parent’s operational control, approval rights, common executives, centralized treasury, or group-wide sales targets can help authorities establish a factual connection between the entities, even when the subsidiary remains legally separate.

Circumstances That Increase Parent Company Exposure

The clearest risk arises when the parent company participates in the corrupt transaction. Examples include approving a suspicious consultant, directing staff to make an off-book payment, setting up a false invoice, or instructing a subsidiary to conceal a benefit from auditors. Communications from parent executives can be especially significant evidence.

Exposure can also increase when the parent receives a direct or indirect benefit. A payment that helps the subsidiary secure a contract may improve consolidated revenue, protect a strategic market, or satisfy a group performance target. Financial benefit alone does not necessarily establish liability, but it can make the parent’s knowledge, incentives, and oversight practices more important.

Shared personnel and centralized decision-making create further risk. If parent-company employees supervise the subsidiary’s sales team, approve high-risk third parties, manage its books, or control government-facing relationships, investigators may view the parent as more than a passive shareholder. The same applies where the subsidiary’s compliance function reports to a parent executive who ignores repeated red flags.

Failure to respond to warnings can be damaging. Red flags may include unusually large commissions, vague consulting agreements, cash payments, requests for payments to personal accounts, public-sector customers, charitable donations linked to procurement, or sudden changes to invoices. A parent that receives such warnings and takes no meaningful action may face allegations of negligent oversight, concealment, or facilitation.

Duties Created By Governance And Compliance Controls

A parent company should establish a governance framework that clearly allocates responsibility for anti-bribery compliance. The framework should identify which controls are mandatory across the group, which risks require local adaptation, who approves exceptions, and how the board or an appropriate committee receives reports.

Policies should cover public-sector bribery, commercial bribery, gifts and hospitality, charitable contributions, sponsorships, facilitation payments, conflicts of interest, third-party intermediaries, and accurate books and records. A translated Chinese version should be available to relevant staff, with examples that reflect local business practices without implying that customary payments are acceptable.

Due diligence should be proportionate to risk. A low-value supplier with no government contact may require basic screening, while a consultant seeking introductions to hospitals, state-owned enterprises, or licensing officials should receive enhanced review. The parent should document beneficial ownership, qualifications, connections to officials, services provided, compensation, banking details, and approval history.

Training is another practical obligation. Employees should know how to identify improper requests, report concerns, preserve records, and escalate pressure from customers or officials. Training should reach sales personnel, procurement staff, finance teams, senior managers, and third parties with meaningful exposure to the business. Completion statistics alone are weak evidence if employees cannot explain the rules in practice.

Financial controls must match the policy. Payments should be made to verified accounts, supported by contracts and evidence of services, and reconciled against approved budgets. Discounts, rebates, commissions, and marketing funds deserve particular attention because they can disguise improper transfers. Parent finance teams should have authority to challenge unusual transactions rather than treating local management approval as sufficient.

Risk Area Parent Company Responsibility Evidence Of Effective Oversight
Third parties Set screening, approval, contracting, and monitoring standards Due diligence files, risk ratings, renewal reviews
Gifts and hospitality Define thresholds, prohibited recipients, and escalation rules Registers, approvals, receipts, exception records
Books and records Require accurate descriptions and supporting documents Audit trails, reconciliations, testing results
Investigations Preserve independence, confidentiality, and escalation routes Investigation protocols, reports, remediation logs
Training Deliver role-specific and local-language instruction Attendance data, assessments, targeted refreshers
Reporting Provide protected channels accessible to subsidiary staff Case logs, response times, non-retaliation records

Investigating Allegations Across The Corporate Group

When an allegation emerges, the parent should first secure relevant evidence and prevent interference. This may include preserving email accounts, messaging applications, expense records, contracts, accounting entries, tender files, travel records, and access logs. A legal hold should cover both the subsidiary and parent personnel who may have directed or reviewed the activity.

The investigation’s structure matters. Investigators should define the allegations, identify potential conflicts, determine the applicable laws, and establish reporting lines to an independent committee or senior legal function. Local management should not control an inquiry into its own conduct. External counsel may be appropriate where criminal exposure, regulator contact, privilege, or cross-border evidence issues are present.

A multinational response must account for Chinese requirements relating to personal information, important data, state secrets, employee privacy, and cross-border transfers. Collecting and exporting employee messages without a lawful basis or proper process can create additional regulatory problems. The team should coordinate forensic collection, translation, interview protocols, and data-transfer decisions before moving large volumes of information outside China.

The practical challenges of a multi-country review are addressed in this guide to cross-border investigations, particularly where different privilege, labor, privacy, and disclosure rules apply. A parent should also avoid making premature public statements or destroying potentially relevant records while the facts remain incomplete.

Reporting, Cooperation, And Remediation Decisions

There is no universal rule requiring a parent to report every suspected payment to a Chinese authority. Reporting duties may arise from the facts, the identity of the recipient, the amount, the company’s licensing or sector obligations, contractual commitments, listing rules, or the laws of another jurisdiction. Legal advice should be obtained before contacting an authority or making a regulatory disclosure.

Foreign enforcement regimes can create a parallel obligation. A parent listed in the United States may face Foreign Corrupt Practices Act concerns involving public officials, accounting controls, or books and records. A company connected to the United Kingdom may face exposure under the UK Bribery Act, including the failure of a commercial organization to prevent bribery by an associated person. Other national laws may apply based on nationality, listing status, payment systems, or territorial links.

Cooperation should be informed rather than automatic. The company should understand the facts, identify potentially applicable authorities, preserve privilege where available, and coordinate statements across jurisdictions. Inconsistent explanations from the parent and subsidiary can deepen suspicion, while carefully documented cooperation may support a more proportionate outcome.

Remediation should address the control failure, not only the individual payment. Possible measures include removing conflicted managers, recovering improper commissions where lawful, suspending high-risk third parties, revising approval thresholds, improving hotline access, conducting targeted audits, and changing sales incentives that reward revenue without regard to compliance. Disciplinary action should be consistent, documented, and free from retaliation against people who raised concerns.

Practical Steps For Parent Company Directors

Directors and senior executives should be able to demonstrate active oversight of corruption risk in China. They do not need to manage every local transaction, but they should receive reliable information, challenge unexplained exceptions, and ensure that compliance has adequate authority, staffing, and access to data.

A regional risk assessment should consider the subsidiary’s industry, customer base, government touchpoints, use of agents, cash intensity, licensing needs, ownership structure, and history of complaints. Country information can support this process, including the India country profile as a comparative resource when a group operates across Asian markets. Comparable regional analysis can reveal where controls should be standardized and where local risks differ.

The following actions help establish a defensible oversight record:

  • Map the parent’s actual influence over the Chinese subsidiary, including shared officers, finance functions, systems, and approval rights.
  • Test high-risk payments, commissions, donations, sponsorships, and distributor discounts against contracts and proof of service.
  • Create a confidential reporting channel that subsidiary employees can use without routing complaints through implicated local managers.
  • Review third-party relationships periodically, especially after changes in ownership, scope of work, compensation, or government-facing activity.
  • Report significant findings to the board or an independent committee, with documented decisions on investigation, disclosure, discipline, and remediation.

Managing Subsidiary Independence Without Losing Control

A parent should avoid two opposite mistakes: treating the Chinese subsidiary as entirely autonomous or imposing controls so rigidly that local employees bypass them. Effective compliance combines group-wide principles with procedures that fit Chinese law, language, business structure, and operational reality.

The parent can preserve legal separation while exercising responsible oversight. Written governance documents should distinguish shareholder rights, board responsibilities, management authority, compliance reporting, and audit access. Centralized functions should have clear mandates, and local leaders should understand when they must escalate an issue rather than resolve it informally.

Joint ventures require particular care. The parent may have limited voting rights but still possess influence through nominated directors, technical support, financing, procurement, or shared personnel. Contracts should address anti-bribery standards, audit rights, information access, training, reporting, and consequences for misconduct. Those rights should be used in practice; unused audit rights provide little protection.

A mature program also measures whether controls work. Useful indicators include overdue due diligence, rejected payments, hotline trends, repeat audit findings, unusual commission levels, training comprehension, and remediation completion. These metrics should be reviewed for quality rather than treated as a box-ticking exercise.

A parent company that treats corruption risk as a shared governance responsibility is better positioned to protect its license to operate, preserve reliable financial reporting, and respond credibly when allegations arise. Review the group’s China controls, document the reasoning behind oversight decisions, and address weaknesses before an isolated subsidiary incident becomes a wider enforcement matter.

copyright © Global Advice Network